@chjara The systemd ProtectXXX= declarations are much more pragmatic IMO, its easy to say “this app doesn’t need /home” and similar